Verification: TOTP Authenticator

Verification: TOTP authenticatorEnterprise Edition+

Introduction

The TOTP Authenticator allows users to bind any authenticator that complies with the TOTP (Time-based One-Time Password) specification (RFC-6238), and perform identity verification using a time-based one-time password (TOTP).

Administrator Configuration

Navigate to the Verification Management page.

Add - TOTP Authenticator

Apart from a unique identifier and title, no additional configuration is required for the TOTP authenticator.

User Binding

After adding the authenticator, users can bind the TOTP authenticator in their personal verification management area.

Warning

The plugin does not currently provide a recovery code mechanism. Once the TOTP authenticator is bound, users are advised to keep it secure. If the authenticator is accidentally lost, they can use an alternative verification method to verify their identity, unbind the authenticator, and then rebind it.

User Unbinding

Unbinding the authenticator requires verification using the already bound verification method.